Uploading data to an AI tool is more than just a casual click — it's an action that can have legal implications.
The law expects organizations to consider several distinct compliance issues governing inputs to an AI tool. Failing to properly follow compliance issues can expose your organization to unexpected legal risk.
This blog walks through the categories of legal exposure discussed in episode six of ZeroDay Law’s Decoding Cyber Law podcast series. As the founder and principal attorney at ZeroDay Law, in this episode, I discuss three specific input categories that should be considered in your AI use policy.
Here’s what to consider.
Prefer to watch the two-minute podcast? Tune in here.
The law doesn't carve out a separate category for AI inputs. Existing rules around ownership, confidentiality, contracts and regulated data apply the moment data enters the tool (and several can apply to the same upload at once).
The categories below are the ones most likely to surface inside real organizations and the ones any AI use policy needs to address head-on regarding inputs.
Loss of trade secret protection is a real risk when proprietary content is uploaded to a third-party platform. If trade secrets are anywhere in scope — yours or a client's — assume an off-the-shelf commercially available AI tool is off-limits. I’m not saying that doing so would necessarily remove any trade secret protection, just that it’s not worth the risk unless you have done some serious work and have control over the model and data store.
Uploading certain data to an AI tool or LLM may breach a Non-Disclosure Agreement (NDA) your organization may have already signed. Most NDAs prohibit disclosure of confidential information to third-party vendors, and this could include AI tools. If so, the moment the data enters the tool, an NDA breach may have occurred.
Before uploading any data, your organization must also consider whether it has the license rights or sufficient IP rights to provide data directly to an AI tool to be used in output, or even to co-mingle it with other data. The risk sharpens when the content didn't originate inside your organization. Copyrighted material represents a broad, deep category of content, from third-party research reports to media clips, stock images and client-owned artwork.
Depending on your industry, you may be subject to sector-specific regulations.
In addition to sector- and geography-specific regulations, a broad array of consumer protection laws can apply to organizational AI use for organizations that offer products and services to consumers.
Deceptive trade practice prohibitions may apply when an organization fails to disclose that it is using AI or fails to disclose that customer data will be used in AI. Risk can also occur when customer data is not clearly segregated from other data inside an AI tool.
Fortunately, data protection and AI use can co-exist if use guidelines are established and followed within your organization.
First, you’ll need to create a solid and realistic AI compliance environment. Let’s focus on how to get started.
Take a deeper look into this topic with our blog post, "What You Need to Know Before Uploading Internal Documents to AI Tools."
Once you understand where the legal exposure sits, the next step is making sure your organizational policies and practices are structured to manage it.
Develop a clear AI use policy that defines what information can and cannot be used or shared, for what purposes, with which tools and under what conditions. Reinforce the policy through ongoing training that keeps team members aware of evolving risks and platform changes.
Strong AI governance isn't a one-time policy launch — it requires a combination of controls, training and ongoing reinforcement that meets your teams where they actually use AI.
Controls only work when staff understand the risks those controls exist to prevent and their role in supporting the controls. Risks can be triggered when an employee doesn't realize that pasting into an AI tool can carry contractual or statutory consequences.
For help in reviewing an existing AI governance policy or putting formal controls in place, reach out to ZeroDay Law. Listen to the Decoding Cyber Law podcast for the full discussion on the legal responsibilities surrounding AI inputs.